Leviathan
MITRE ATT&CK: G0065 View on attack.mitre.org
Aliases: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon, Leviathan, GADOLINIUM, KRYPTONITE PANDA, ATK29, TA423, Red Ladon, ITG09, ISLANDDREAMS, JJDoor, Feverdream
- First seen
- 2009-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 118 (115 malicious)
- Last IoC activity
- 2026-09-02 00:38:30
- Profile updated
- 2026-07-07 12:33:00
Targeted industries: defense-and-aerospace education-and-nonprofits healthcare-and-pharmaceutical government-and-public-sector manufacturing transportation-and-logistics
Targeted regions: country_code:us country_code:ca country_code:au country_code:cn country_code:gb country_code:fr country_code:de
Context
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.
Recent IoC activity
115 malicious indicators in Maltiverse are attributed to Leviathan (G0065). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.nullsecurity.net | 2026-09-03 | 1 |
| hostname | ns-3.open.ro | 2026-09-03 | 1 |
| hostname | autodiscover.email | 2026-09-03 | 1 |
| hostname | autodiscover.exchange | 2026-09-03 | 1 |
| hostname | ultrasocial.info | 2026-09-03 | 2 |
| hostname | autoconfig.email | 2026-09-03 | 1 |
| hostname | usdagroup.com | 2026-09-03 | 3 |
| hostname | mail.pics | 2026-09-03 | 1 |
| hostname | prod.tools | 2026-09-02 | 1 |
| hostname | webdisk.us | 2026-09-02 | 1 |
| hostname | autodiscover.host | 2026-09-02 | 1 |
| hostname | admin.dev | 2026-09-02 | 1 |
| hostname | airbusocean.com | 2026-09-02 | 3 |
| hostname | autodiscover.it | 2026-09-02 | 1 |
| hostname | made.by | 2026-09-02 | 1 |
| hostname | thyssenkrupp-marinesystems.org | 2026-09-02 | 4 |
| hostname | www.cantrip.org | 2026-09-02 | 1 |
| hostname | test.support | 2026-09-02 | 1 |
| hostname | mail.news | 2026-09-02 | 1 |
| hostname | webdisk.it | 2026-09-02 | 1 |
Detection coverage
- 155 YARA rules
- 821 Sigma rules
Malware & tools used
- Exfiltration to Cloud Storage (attack-pattern)
- Vulnerability Scanning (attack-pattern)
- One-Way Communication (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- SSH (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Credentials (attack-pattern)
- LSASS Memory (attack-pattern)
- Social Media Accounts (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Binary Padding (attack-pattern)
- Domains (attack-pattern)
- Email Accounts (attack-pattern)
- Spearphishing Link (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Steganography (attack-pattern)
- Social Media Accounts (attack-pattern)
- PowerShell (attack-pattern)
- Shortcut Modification (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Server (attack-pattern)
Related threat objects
- GADOLINIUM (threat-actor)
Reports & references
- Mandiant — Apt Groups (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- CrowdStrike — Two Birds One Stone Panda (report)
- Microsoft — Rwmfii (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
- proofpoint.com — Leviathan Espionage Actor Spearphishes Maritime And Defense Targets (report)
- Mandiant — Suspected Chinese Espionage Group Targeting Maritime And Engineering Industries (report)
- cfr.org — Apt 40 (report)
- Mandiant — Apt40 Examining A China Nexus Espionage Actor (report)
- recordedfuture.com — Chinese Threat Actor Tempperiscope (report)
- Mandiant — Chinese Espionage Group Targets Cambodia Ahead Of Elections (report)
- MITRE ATT&CK — G0065 (report)
- intrusiontruth.wordpress.com — What Is The Hainan Xiandun Technology Development Company (report)
- intrusiontruth.wordpress.com — Who Is Mr Gu (report)
- intrusiontruth.wordpress.com — Who Else Works For This Cover Company Network (report)
- intrusiontruth.wordpress.com — Who Is Mr Ding (report)
- intrusiontruth.wordpress.com — Hainan Xiandun Technology Company Is Apt40 (report)
- secureworks.com — Bronze Mohawk (report)
- mycert.org.my — Advisory (report)
- elastic.co — Advanced Techniques Used In Malaysian Focused Apt Campaign (report)
- Microsoft — Gadolinium Detecting Empires Cloud (report)
- justice.gov — Four Chinese Nationals Working Ministry State Security Charged Global Computer Intrusion (report)
- justice.gov — Download (report)
- justice.gov — Download (report)
Attributed from
- APT40 Recent Tradecraft (Deprecated) (campaign)
- Leviathan Australian Intrusions (campaign)
External references
- mitre-attack — G0065
- MUDCARP
- Kryptonite Panda
- Gadolinium
- BRONZE MOHAWK
- Gingham Typhoon
- Leviathan
- TEMP.Jumper
- TEMP.Periscope
- Accenture MUDCARP March 2019
- Crowdstrike KRYPTONITE PANDA August 2018
- Proofpoint Leviathan Oct 2017
- MSTIC GADOLINIUM September 2020
- CISA Leviathan 2024
- CISA AA21-200A APT40 July 2021
- APT40
- FireEye Periscope March 2018
- Microsoft Threat Actor Naming July 2023
- FireEye APT40 March 2019
- SecureWorks BRONZE MOHAWK n.d.